RE: pushing exploits through the Firewall

From: Enrique A. Sanchez Montellano (enrique.sanchez@hypersec.co.uk)
Date: Sun Feb 12 2006 - 13:30:05 EST


Ok Ill answer between ============ as usual =)

-----Mensaje original-----
De: Mike Gilligan [mailto:mikewgilligan@hotmail.com]
Enviado el: Domingo, 12 de Febrero de 2006 02:42 a.m.
Para: pen-test@securityfocus.com
Asunto: pushing exploits through the Firewall

Hi group
Say a pentester manages to discover a vulnerable version of BIND running on
an external DNS server and has successfully sourced an exploit for the vuln.

==================
Sounds doable and usable =)
==================

I'm curious how it would be possible to launch the exploit against the
server when a packet filtering device and stateful inspection Firewall sit
between the pentester and the vuln host. It would seem at first glance that
this is not a viable option. How else might one go about exploiting the
vuln?

==================
I would just run the exploit, unless you have an IPS you are pretty much
doable since well firewall is just a filter, should let the port 53 go, if
you have one of tose 1 does it all then just change the shellcode or rewrite
the exploit, ala maybe sending tons of broken up packets and using IDS
bypassing techniques ....

Encrypted shellcodes work nicely to, have it exchange rc4 keys and voila it
wont detect the uname -a;id trigger string again if it has the IDS module
on, a simple firewall should just let you pass =)
==================

Mike

_________________________________________________________________
Get MSN Hotmail alerts on your mobile.
http://mobile.msn.com/ac.aspx?cid=uuhp_hotmail

----------------------------------------------------------------------------

--
Audit your website security with Acunetix Web Vulnerability Scanner: 
Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are
futile against web application hacking. Check your website for
vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers
do! 
Download Trial at:
http://www.securityfocus.com/sponsor/pen-test_050831
----------------------------------------------------------------------------
---
------------------------------------------------------------------------------
Audit your website security with Acunetix Web Vulnerability Scanner: 
Hackers are concentrating their efforts on attacking applications on your 
website. Up to 75% of cyber attacks are launched on shopping carts, forms, 
login pages, dynamic content etc. Firewalls, SSL and locked-down servers are 
futile against web application hacking. Check your website for vulnerabilities 
to SQL injection, Cross site scripting and other web attacks before hackers do! 
Download Trial at:
http://www.securityfocus.com/sponsor/pen-test_050831
-------------------------------------------------------------------------------


This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:55:30 EDT